---
name: Narco-Check
slug: narco-check
category: AI Engineering
description: "Narco-Check audits an agent's memory for hallucinations, circular confirmations, and state poisoning when triggered by repeated failures or the nightly deep dive. It grounds checks in real system state and flags poisoned memory entries before proceeding."
github: "https://github.com/open-gitagent/opengap/tree/main/examples/jason-my-claw-is-the-law-deebee-4567b4/skills/narco-check"
language: TypeScript
stars: 2916
forks: 346
install: "npx degit https://github.com/open-gitagent/opengap/tree/main/examples/jason-my-claw-is-the-law-deebee-4567b4/skills/narco-check ~/.claude/skills/narco-check"
installs_to: ~/.claude/skills/narco-check
source_path: examples/jason-my-claw-is-the-law-deebee-4567b4/skills/narco-check/SKILL.md
collection_size: 18
category_size: 2451
collection_url: "https://dirskills.com/collections/open-gitagent/opengap"
added: 2026-08-17T07:10:04.697Z
last_synced: 2026-08-17T07:10:04.697Z
canonical_url: "https://dirskills.com/skills/narco-check"
---

# Narco-Check

Narco-Check audits an agent's memory for hallucinations, circular confirmations, and state poisoning when triggered by repeated failures or the nightly deep dive. It grounds checks in real system state and flags poisoned memory entries before proceeding.

**Install:**

```bash
npx degit https://github.com/open-gitagent/opengap/tree/main/examples/jason-my-claw-is-the-law-deebee-4567b4/skills/narco-check ~/.claude/skills/narco-check
```

## README

# Narco-Check — Memory Integrity Audit

## When This Runs

1. **Failure trigger:** 2 consecutive failures on the same task or tool
2. **End-of-day trigger:** Nightly deep dive audit (~3 AM)

## Audit Model

Must use `openrouter/anthropic/claude-opus-4.6`. Never run narco-check on a tier-0 or tier-1 model.

```bash
openclaw agent --model openrouter/anthropic/claude-opus-4.6 \
  --message "$(cat ~/.openclaw/workspace/skills/narco-check/audit-prompt.md)" \
  --mode now
```

## 5-4-3-2-1 Grounding Check

Run this first — before reading any logs. Anchors the audit in real system state.

**5 — Run five commands, paste raw output verbatim:**
```bash
date
hostname
df -h /
docker ps --format "table {{.Names}}\t{{.Status}}"
cat ~/.openclaw/workspace/HEARTBEAT.md | head -3
```

**4 — Confirm four workspace files exist, paste first line:**
```bash
head -1 ~/.openclaw/workspace/IDENTITY.md
head -1 ~/.openclaw/workspace/SOUL.md
head -1 ~/.openclaw/workspace/MEMORY.md
head -1 ~/.openclaw/workspace/HEARTBEAT.md
```

**3 — Ping three endpoints, report HTTP codes:**
```bash
curl -s -o /dev/null -w "%{http_code}" http://localhost:18789/health
curl -s -o /dev/null -w "%{http_code}" --max-time 5 https://geniewars.com
curl -s -o /dev/null -w "%{http_code}" --max-time 5 https://siliconchimps.com
```

**2 — Run one Exa search, paste first real result:**
```bash
~/.openclaw/workspace/skills/exa-search/exa.sh "$(date +%Y) advance reader community" 2
```

**1 — State one provable fact:**
```
GROUNDED: [claim] — verified by [command] — output: [exact output]
```

A grounded check with failures is valid. A grounded check with fabricated output is **POISONED**.

## Audit States

- `CLEAN` — no failures, no audit triggered
- `DEGRADED` — issues found, state acceptable, resumed with different approach
- `POISONED` — contaminated entries found, stop and notify Ludo

If POISONED: mark affected MEMORY.md entries `[QUARANTINE YYYY-MM-DD]`, notify Ludo via Slack DM before proceeding.
